BlueNoroff, a financially motivated threat cluster linked to the Lazarus Group, has been observed deploying a highly sophisticated “fake meeting” phishing kit.
That goes far beyond traditional lures, enabling webcam capture, Microsoft Defender evasion, and targeted cryptocurrency credential theft.
New research from JUMPSEC provides rare source-level visibility into the operation after attackers mistakenly exposed JavaScript source maps on live infrastructure, allowing analysts to reconstruct the full attack lifecycle across Windows and macOS environments.
Unlike earlier campaigns that relied on simple spoofed meeting pages, this operation functions as a structured victim acquisition platform.
The attackers combine compromised industry contacts, particularly via Telegram, with tailored social engineering and wallet reconnaissance to selectively target high-value cryptocurrency users.
The exposed source code reveals fully developed Zoom and Microsoft Teams impersonation kits, with evidence suggesting a potential Google Meet variant referenced through infrastructure artifacts like “googie.us-gmeet.com.”
The phishing pages are built as single-page applications, capable of mimicking legitimate meeting workflows while silently executing reconnaissance scripts.
Once a victim accesses the link typically sent from a hijacked, trusted contact the platform initiates webcam access via WebRTC and streams video directly to attacker-controlled panels.
Simultaneously, the kit performs extensive browser-based cryptocurrency wallet fingerprinting using techniques such as EIP-6963 provider discovery, legacy window.ethereum probing, and enumeration of non-EVM wallets like Solana.
This reconnaissance enables operators to identify high-value targets before deploying malware, significantly increasing operational efficiency.
Pivoting across passive DNS, VirusTotal, urlscan.io and reverse DNS data expanded the investigation beyond the original infrastructure set, uncovering additional campaign infrastructure.

The social engineering component is particularly advanced. Victims are guided through a realistic meeting simulation where attackers deploy deepfake video overlays and scripted chat interactions.
Within seconds, victims are prompted to install a fake “Zoom SDK update,” which leverages a ClickFix-style clipboard hijacking technique. Even benign copy actions result in malicious PowerShell payloads being executed, initiating the infection chain.
JUMPSEC has obtained and analysed the source code behind an active BlueNoroff phishing kit used to impersonate Zoom and Microsoft Teams meetings.
On Windows systems, the attack begins with a lightweight PowerShell loader that downloads and executes a VBScript implant identified as Trojan.NukeSped, a malware family historically associated with Lazarus operations.
BlueNoroff Fake Meeting Kit
The script establishes persistence, disables Microsoft Defender through exclusion policies, and performs system reconnaissance via WMI queries.
Aligns with BlueNoroff’s long-standing objective of funding North Korean state operations through attacks on financial institutions and Web3 platforms, as previously documented by CISA and Kaspersky in campaigns such as “GhostCall.”

It also enumerates browser extensions across Chromium-based and Firefox browsers to identify installed cryptocurrency wallets such as MetaMask.
Notably, the malware includes functionality to detect Telegram session artifacts stored in IndexedDB.
This enables attackers to hijack active Telegram sessions, reinforcing a self-propagating infection loop where compromised accounts are reused to target additional victims.
JUMPSEC observed this recursive model in multiple cases, consistent with previously reported BlueNoroff tradecraft.

The macOS variant follows a parallel execution model using shell scripts and Mach-O binaries. A fake Teams or Zoom installer acts as a decoy while background processes deploy a credential stealer.
Analysis of recovered samples, including “ZoomSDK.bin” variants on VirusTotal, shows rapid evolution from simple droppers to fully integrated stealers with LLVM-based obfuscation.
The stealer abuses the macOS security CLI to extract Keychain credentials, particularly Chrome-stored passwords, and exfiltrates them via hardcoded Telegram bot infrastructure.
Infrastructure analysis identified at least eleven initial command-and-control domains, with further expansion through passive DNS and OSINT techniques revealing a broader active network as of July 2026.
The reuse of modules across Zoom and Teams variants, including shared cryptographic execution functions, confirms a unified development pipeline.
This campaign underscores a shift in BlueNoroff operations toward scalable, intelligence-driven targeting that blends technical exploitation with human trust abuse.
By weaponizing legitimate relationships and integrating reconnaissance directly into phishing workflows, the group has significantly increased its success rate against high-value cryptocurrency stakeholders.
Indicators of Compromise
| SHA256 | Type | Size | Detection | Notes |
| 7a0b96f1063593a2e76f2f92ddfe091776a2ba63bc4f87f83dc5ebb675309d8d | PowerShell | 516 B | 11/65 | Loader (zoom.05ukweb.uk variant) |
| 180f797723bd65e82189eb1f737d39ce522614a182e2b46b51faeb49953a412f | PowerShell | 514 B | 16/60 Trojan.SLoad | Loader (weekly-up.online variant) |
| 8889f1b67aea6896945506dae192326149f6c5db87e9b04fa08ac9a142a87775 | VBScript | 16,595 B | 21/62 Trojan.NukeSped | C2 implant (callsdk.online, +Telegram detection) |
| a86659dff126be72aff1d5e546baff735dcb7ed6ddd521737e7e3be8910c05f2 | VBScript | 13,676 B | 27/62 Trojan.SLoad | C2 implant (weekly-up.online) |
| 26bdad9189f6b28a90165c09ceed4386eff2fb352bea7fb78ebb164f28ebed28 | Shell script | 4,887 B | 0/60+ (FUD) | Template dropper (parameterised) |
| 163e4a72cbe392c073eddc60aee69dc1cf87ce492c375af74e923d75d8084683 | Shell script | 4,651 B | 0/62 (FUD) | Deployed dropper (hardcoded weekly-up.online) |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
What Features Should AI SOC Have in 2026? A Complete Checklist : Download the AI SOC Features Checklist


.webp?w=356&resize=356,220&ssl=1)


